diff options
Diffstat (limited to 'roles/settings/templates')
| -rw-r--r-- | roles/settings/templates/archlinux-pam-pw.j2 | 45 | ||||
| -rw-r--r-- | roles/settings/templates/debian-pam-pw.j2 | 49 |
2 files changed, 0 insertions, 94 deletions
diff --git a/roles/settings/templates/archlinux-pam-pw.j2 b/roles/settings/templates/archlinux-pam-pw.j2 deleted file mode 100644 index 7be41ccb..00000000 --- a/roles/settings/templates/archlinux-pam-pw.j2 +++ /dev/null @@ -1,45 +0,0 @@ -#%PAM-1.0 - -auth required pam_faillock.so preauth -# Optionally use requisite above if you do not want to prompt for the password -# on locked accounts. --auth [success=2 default=ignore] pam_systemd_home.so -auth [success=1 default=bad] pam_unix.so try_first_pass nullok -auth [default=die] pam_faillock.so authfail -auth optional pam_permit.so -auth required pam_env.so -auth required pam_faillock.so authsucc -# If you drop the above call to pam_faillock.so the lock will be done also -# on non-consecutive authentication failures. - --account [success=1 default=ignore] pam_systemd_home.so -account required pam_unix.so -account optional pam_permit.so -account required pam_time.so - -{% if settings_pw_policy_enabled %} --password [success=2 default=ignore] pam_systemd_home.so -password requisite pam_pwquality.so retry=3 \ - difok={{ settings_pw_policy_difok }} \ - minlen={{ settings_pw_policy_minlen }} \ - dcredit={{ settings_pw_policy_dcredit }} \ - ucredit={{ settings_pw_policy_ucredit }} \ - ocredit={{ settings_pw_policy_ocredit }} \ - lcredit={{ settings_pw_policy_lcredit }} \ - minclass={{ settings_pw_policy_minclass }} \ - maxrepeat={{ settings_pw_policy_maxrepeat }} \ - maxclassrepeat={{ settings_pw_policy_maxclassrepeat }} \ - gecoscheck={{ settings_pw_policy_gecoscheck }} -{% else %} --password [success=1 default=ignore] pam_systemd_home.so -{% endif %} -password required pam_unix.so try_first_pass \ - nullok \ - shadow \ - minlen={{ settings_pw_policy_minlen }} -password optional pam_permit.so - --session optional pam_systemd_home.so -session required pam_limits.so -session required pam_unix.so -session optional pam_permit.so diff --git a/roles/settings/templates/debian-pam-pw.j2 b/roles/settings/templates/debian-pam-pw.j2 deleted file mode 100644 index 521b822a..00000000 --- a/roles/settings/templates/debian-pam-pw.j2 +++ /dev/null @@ -1,49 +0,0 @@ -# -# /etc/pam.d/common-password - password-related modules common to all services -# -# This file is included from other service-specific PAM config files, -# and should contain a list of modules that define the services to be -# used to change user passwords. The default is pam_unix. - -# Explanation of pam_unix options: -# The "yescrypt" option enables -#hashed passwords using the yescrypt algorithm, introduced in Debian -#11. Without this option, the default is Unix crypt. Prior releases -#used the option "sha512"; if a shadow password hash will be shared -#between Debian 11 and older releases replace "yescrypt" with "sha512" -#for compatibility . The "obscure" option replaces the old -#`OBSCURE_CHECKS_ENAB' option in login.defs. See the pam_unix manpage -#for other options. - -# As of pam 1.0.1-6, this file is managed by pam-auth-update by default. -# To take advantage of this, it is recommended that you configure any -# local modules either before or after the default block, and use -# pam-auth-update to manage selection of other modules. See -# pam-auth-update(8) for details. - -# here are the per-package modules (the "Primary" block) -{% if settings_pw_policy_enabled %} -password requisite pam_pwquality.so retry=3 \ - difok={{ settings_pw_policy_difok }} \ - minlen={{ settings_pw_policy_minlen }} \ - dcredit={{ settings_pw_policy_dcredit }} \ - ucredit={{ settings_pw_policy_ucredit }} \ - ocredit={{ settings_pw_policy_ocredit }} \ - lcredit={{ settings_pw_policy_lcredit }} \ - minclass={{ settings_pw_policy_minclass }} \ - maxrepeat={{ settings_pw_policy_maxrepeat }} \ - maxclassrepeat={{ settings_pw_policy_maxclassrepeat }} \ - gecoscheck={{ settings_pw_policy_gecoscheck }} -password [success=1 default=ignore] pam_unix.so obscure use_authtok try_first_pass yescrypt -{% else %} -password [success=1 default=ignore] pam_unix.so obsecure sha512 minlen={{ settings_pw_policy_minlen }} -{% endif %} -# here's the fallback if no module succeeds -password requisite pam_deny.so -# prime the stack with a positive return value if there isn't one already; -# this avoids us returning an error just because nothing sets a success code -# since the modules above will each just jump around -password required pam_permit.so -# and here are more per-package modules (the "Additional" block) -password optional pam_gnome_keyring.so -# end of pam-auth-update config |
